TGViewer
Channel Public Channel
Surge TestFlight Feed

Surge TestFlight Feed

@surgetestflightfeed

This channel provides information about the latest beta versions of Surge for iOS, Mac, and tvOS.
Subscribers
12.9K
Photos
19
Videos
1
Links
63
Recent Posts 20 shown
Post #413 7.93K
Beta Updates

- A category parameter has been added to policy groups for grouped display. It can be used when there are many policy groups.
- All test-url parameters now support configuring HTTPS URLs for testing. The test result remains the latency of a single HTTP RTT, but due to the TLS handshake, the test duration may increase significantly when there are many policies.
- In the previous version, MITM security was strengthened by generating a separate key pair for each distinct domain name. This caused noticeable delays when performing MITM concurrently on a large number of different domains. After evaluation, this change has been reverted.
Post #412 4.64K
Surge Mac 6.9.1 & Surge iOS 5.22.1 are now available.

New Features
- [iOS] Policy group widgets now support the extra-large size on iOS 27.
- [iOS] Added a medium-sized iOS widget with start/stop controls, running status, and one-tap switching between Rule-Based Proxy, Direct Outbound, and Global Proxy.
- Added UNKNOWN support to GEOIP and IP-ASN rules, allowing IP addresses without matching country or ASN database entries to be matched. This works in both individual rules and rule sets.

Fixes and Improvements
- Fixed lower-than-expected results under extreme throughput performance testing.
- Fixed failed cellular backup connections in Wi-Fi Assist or Hybrid mode prematurely aborting an ongoing Wi-Fi connection attempt.
- Fixed Pre-Matching remaining enabled after changing a rule to a non-reject policy or unsupported rule type.
- Fixed Hysteria UDP forwarding with servers where HTTP/3 Datagram negotiation interfered with UDP traffic.
- Fixed missing traffic statistics for UDP connections through proxies and tunnels, including WireGuard and Tailscale.
- Fixed a rare issue where closing a UDP proxy connection during packet reception could stall other Surge traffic.
- Fixed SF Symbol policy-group icons not responding correctly to appearance changes on iOS.
- [iOS] Improved resource updates on iOS: pending automatic updates resume when the app becomes active, duplicate downloads are avoided, and stale errors are cleared after a successful background refresh.
- [Mac] Fixed macOS Smart policy group context menus showing outdated usage or incorrect priority adjustments.
- [Mac] Fixed unnecessary Surge Helper installation or upgrade alerts at startup when the enabled features do not require the helper.
  • ❤ 4
  • 👍 1
  • 🥰 1
Post #411 7.31K
* [Host] domain aliases can specify a dedicated DNS server.
* Updated the IPv6 fake-IP range to avoid unnecessary browser local-network permission prompts.
* Fixed rare crashes when proxy or QUIC connections close synchronously during data processing.
* Fixed recursive HTTP/3 timer processing that could cause a stack overflow.
* Fixed QUIC connections stalling after receive-side backpressure.
* Fixed long-running Ponte and Vector sessions eventually exhausting their ability to open relayed streams.
* Fixed rare deadlocks involving cron-script shutdown and Vector UDP connections.
* Improved stability during heavy connection churn and local-port exhaustion.
* Improved MITM certificate generation and certificate-chain handling.
* Fixed several additional crashes and minor issues.
  • 🎉 9
  • ❤ 6
  • 🤔 2
  • 👍 1
Post #410 6.56K
Surge iOS 5.22.0 is now available on the App Store.

New Features

* Added a full-featured Terminal to Surge iOS, providing CLI-based diagnostics, rule explanations, policy-group inspection, command completion, and command history.
* Added MASQUE proxy support using HTTP/3 CONNECT and CONNECT-UDP.
* HTTP/2 CONNECT proxies can now relay UDP traffic with udp-relay=true.
* TrustTunnel can now use HTTP/3 transport with h3=true.
* Added group-level proxy chaining. Policy groups can connect concrete proxy members through an underlying proxy.
* Added a Prometheus-compatible /metrics endpoint to the HTTP Controller.
* Added a graphical Policy Priority editor for Smart Groups.
* Added event-script support for engine-started and profile-reloaded.
* Added notification controls for proxy clients, scripts, and rule matches.
* Added Arctic and Pulse app icons.

Tailscale

* Added peer-relay support through eligible tailnet devices, with Direct → Peer Relay → DERP priority and runtime latency information.
* Interactive sign-in now supports tailnets that require administrator device approval.
* Improved recovery from interrupted sign-in by reconnecting and continuing the existing authorization flow.
* Improved compatibility with the Tailscale administration console and version-gated operations.
* Fixed connectivity issues after the control server assigns a new tailnet address.
* Improved recovery after network changes, UDP binding failures, expired connections, and in multi-peer configurations.

Profiles, Includes, and Rulesets

* #include directives can now be freely combined with regular section content.
* Sections using multiple or mixed includes are presented as read-only when their write-back destination is ambiguous.
* Added wildcard detached-section includes for [Ruleset *], [WireGuard *], and [Tailscale *].
* Added DEVICE_NAME to the profile environment for use in #!REQUIREMENT.
* Added diagnostics for missing WireGuard and Tailscale configuration sections and clarified named-include behavior.
* Local and inline rulesets can now be edited graphically on macOS and iOS.
* Rulesets can reference other inline rulesets as well as external RULE-SET or DOMAIN-SET sources.
* Circular ruleset references are rejected with a clear reference chain.
* The ruleset editor now better preserves blank lines, comments, disabled rules, and source locations.
* Fixed rules created inside rulesets or logical rules retaining an unintended hidden policy value.
* Improved selection of the appropriate write-back target when mixed includes are used.
* Fixed [General] values containing #, //, or ; being altered after saving.
* Profiles changed on disk or through iCloud now reload automatically, while invalid updates leave the working configuration active.
* Module installation state is no longer governed directly by iCloud.
* Cloud synchronization now excludes .git and node_modules.

UI and Editing

* The bottom tab bar remains visible during navigation to avoid UIKit transition glitches.
* The Script Editor now uses a dedicated modal interface with an improved toolbar and keyboard layout.
* Remote Controller and Ponte Diagnostics are available for all Ponte devices, including shared devices.
* Improved policy-group icon handling across themes and profile reloads.
* Improved iOS 26 context menus, previews, and module presentation.
* Virtual IP records and search results now use self-sizing rows.
* Fixed policy groups using an underlying proxy being unavailable from the UI.
* Improved module error reporting for download, parsing, writing, and installation failures.

Networking and Reliability
  • ❤ 7
Post #409 5.03K
Surge Mac 6.9.0 is Now Available

* MASQUE & HTTP/3 — Added MASQUE proxy support with HTTP/3 CONNECT and CONNECT-UDP, plus HTTP/3 transport for TrustTunnel.
* Tailscale Peer Relay — Added Peer Relay support with Direct → Peer Relay → DERP path selection, plus improved sign-in and connectivity recovery.
* Surge CLI — Significantly expanded the CLI with rule explanations, DNS tracing, HTTP probing, runtime diagnostics, VM Gateway inspection, and more.
* Proxy Chaining — Policy groups can now route their proxy members through an underlying proxy.
* Profile System — #!include can now be freely mixed with inline content, with wildcard includes for Ruleset, WireGuard, and Tailscale sections.
* New Editors — Redesigned major configuration interfaces and added graphical editors for rulesets and Port Forwarding.
* Prometheus Metrics — Added a Prometheus-compatible /metrics endpoint for runtime and traffic monitoring.
* Gateway & Reliability — Improved IPv6 Gateway Mode and reliability across QUIC, DNS, Ponte, Vector, and high-connection-load scenarios.

For the complete release notes, please visit:
https://nssurge.com/support/mac/release-notes
Nssurge Surge Mac - Advanced Web Debugging Proxy for Mac & iOS Surge for Mac
  • ❤ 8
  • 👍 1
Post #408 7.08K
Beta Updates

Improved

- Nested rulesets now work reliably: inline rulesets can reference other inline rulesets or external RULE-SET and DOMAIN-SET sources. Circular references are rejected with a clear reference chain instead of causing recursive matching.
- The local ruleset editor now preserves blank lines, standalone and trailing comments, and disabled rules more accurately. Invalid entries report their source file and line number, while comment rows use the same readable presentation as the main rule editor.
- Virtual IP records and search results on iOS now use self-sizing rows, preventing longer domains and usage details from being clipped.

Fixed

- Fixed rules added inside a ruleset or logical rule on iOS incorrectly retaining a hidden policy value when saved.
  • ❤ 6
  • 👍 1
Post #407 8.12K
Beta Updates

- Tailscale can now establish peer-relay paths through eligible tailnet devices when a direct connection is unavailable, with Direct > Peer Relay > DERP path priority. Runtime details identify Peer Relay connections and display their latency.
- Local-file and inline rulesets can now be edited graphically on macOS and iOS. Add or modify standard rules, logical rules, nested rulesets, and comments, then reorder or remove entries as needed. Create new inline rulesets directly from the rule editor and store them as named [Ruleset ...] sections in the profile.
- The previously added mixed use of #include will no longer affect UI write-back for the corresponding sections. Surge will automatically select the write-back target as accurately as possible based on the changes.
  • ❤ 2
Post #406 6.95K
Beta Updates

macOS Interface

- Reworked the proxy editor, policy-group editors, parameter dialogs, and the General, Interface, DNS, Profile, and License pages using a new System Settings-style card interface.

Surge CLI & Remote Control

- Added restart-engine, which completely restarts the engine, closes active connections, and clears caches and temporary rules.
- reload continues to apply only changed profile sections whenever possible, preserving unaffected runtime state.
- Restart Engine is also available from Surge Dashboard and the iOS Remote Controller maintenance menu.

Tailscale

- Improved compatibility with the Tailscale administration console. Surge devices are no longer incorrectly reported as using an outdated client, enabling version-gated operations such as editing the device IP address.

iOS

- Fixed managed-profile icon-url icons being hidden by automatically generated placeholder icons.
- Custom policy-group icons now behave consistently across Lucid and Gradient themes, with a Default option available in both.
- Module download, parsing, file-writing, and installation-information failures are now reported instead of failing silently.
- Refined the Script Editor toolbar and file-selection layout on iOS 26.
- Improved context-menu previews on iOS 26 by following the system’s native corner styling.
  • 👍 11
  • 🤩 1
Post #405 5.64K
Profile System Updates

The #include directive can now be freely combined with other content within a section. The following usage patterns are supported:

1. Dedicated Include

[Proxy]
#include proxy.dconf

When a section consists of a single #include directive, it remains fully editable in the UI. Any changes made through the UI will be correctly written back to proxy.dconf.

2. Multiple Includes

[Proxy]
#include a.dconf, b.dconf

This combines content from multiple files into a single section. Since the UI cannot determine how changes should be written back to the individual files, the section becomes read-only and cannot be modified through the UI.

3. Mixed Content and Includes (New)

[Rule]
#include common-rule-a.dconf
DEST-PORT,123,DIRECT
#include common-rule-b.dconf

#include directives can now be freely mixed with regular content within the same section. As with multiple includes, the UI cannot determine the appropriate write-back behavior, so the section will be read-only.

Note: When using this feature in the [Rule] section, keep in mind that a FINAL rule immediately terminates rule matching. Any rules included or defined after it will therefore never be evaluated.
  • 👍 18
Post #404 5.2K
Beta Updates

Smart Group

- Added a graphical Policy Priority editor for Smart Groups on macOS and iOS.

Tailscale

- Interactive sign-in now supports tailnets that require administrator device approval. Surge clearly indicates when sign-in has completed but the device is still awaiting approval.
- Fixed Tailscale traffic becoming unavailable when the control server assigned the device a new tailnet address.
- Improved recovery after network changes by retrying temporarily failed UDP bindings and refreshing direct-connect endpoints.
- Improved WireGuard and Tailscale handling of multiple peers and expired connections.

Profile and Automation

- On iOS, profile changes made on disk or received through iCloud now reload automatically. If the updated profile is invalid, Surge keeps the working configuration active and reports the error.
- Event scripts can now respond to engine-started and profile-reloaded, in addition to network-changed.

Notifications

- Added notification controls for new proxy clients, script notifications, and rule-matched notifications.
- Local and remote notification category settings now correctly apply to dynamically generated alerts.
- Disabling policy-group change notifications now also suppresses temporary group-override alerts.

Fixed

- Improved MITM certificate generation by using separate keys for generated leaf certificates and correcting the transmitted certificate chain.
- Fixed QUIC connections potentially stalling after receive-side backpressure.
- Fixed rare deadlocks involving cron-script shutdown and Vector UDP connections, including Ponte traffic.
- Improved stability under heavy connection churn and local-port exhaustion.
- Other small UI issues.
  • ❤ 5
Post #403 5.24K
UniFi Controller Integration (Beta)

When Surge is operating in DHCP mode, Dashboard device management can integrate with the UniFi Controller. You can directly view the corresponding device’s SSID, AP, Wi-Fi version, and other information in Surge’s Dashboard. You can also force a specific device to reconnect.

Meanwhile, this feature is provided entirely by a new, extensible plugin mechanism, allowing plugins to be written to support any AP Controller or router.

This feature is currently in beta, so no UI configuration interface is provided yet. It can only be configured through surge-cli or the AI Skill. After installing the Surge AI Skill, simply ask the AI to help integrate your UniFi AP Controller. Alternatively, ask the AI to write a new plugin based on your router.

Plugin System (Beta)

- Added the Surge Plugin System on macOS. Plugins run as isolated JavaScript extensions independent of the active profile.
- The first supported plugin type is ap-controller, which can supply Wi-Fi information for the device panel and reconnect wireless clients. The existing UniFi Controller integration is now provided as a built-in plugin.

As it is still in the beta phase, the mechanism for installing plugins remotely via plugin install has not yet been enabled. Currently, only loading and running local content via plugin load is supported.
  • ❤ 20
Post #402 5.97K
Profile System Updates
- Added wildcard detached-section includes for [Ruleset *], [WireGuard *], and [Tailscale *]. A single #!include can now load all matching named sections from another local or remote profile file.
- Added DEVICE_NAME to the profile environment, enabling device-specific conditions in #!REQUIREMENT.
- [Mac] The current Reload Profile option will compare the differences between the old and new profiles and apply only the changes. It will not terminate existing active connections unless necessary. (Same behavior as editing through the UI previously.)
- [Mac] Added a Restart Engine option, which behaves like Reload Profile in the previous version and completely restarts the core once.
  • 👍 17
  • ❤ 2
Post #401 6.05K
Beta Updates

### Surge CLI

- Added vmnet status to inspect the VMNET interface configuration, including addresses, prefixes, MTU, and diagnostic table sizes.
- Added vmnet arp to inspect IPv4 neighbors learned from Gateway Mode clients.
- Added vmnet ndp to inspect the IPv6 neighbor table.
- Added vmnet ra to inspect IPv6 Router Advertisement takeover status, including clients, known routers, RA lifetimes, and blacklisted devices.

### macOS

- Added a graphical Port Forwarding editor for creating and managing incoming TCP forwarding rules. Listening address, listening port, destination, and outbound policy can all be configured without editing the profile manually.
- Gateway-related device actions are now hidden when Gateway Mode is unavailable.
- Fixed system proxy settings being applied when using VIF mode without a default route.

### iOS UI

- When navigating to a new page, the bottom tab bar is no longer hidden. This change was made to avoid triggering known UIKit UI glitches that can occur when the tab bar is hidden during push transitions.
- The Script Editor now opens in a dedicated modal interface, with an updated toolbar, close action, and improved keyboard layout.
- Remote Controller and Ponte Diagnostics are now available for all Ponte devices, including devices shared by another iCloud account.
- Other UI improvements.

### Other Improvements

- Updated the IPv6 fake-IP range to avoid unnecessary browser local-network permission prompts, while retaining compatibility with previously cached addresses.
- Proxy connections closed during the protocol handshake now provide a clearer error message, with guidance to verify credentials, encryption methods, and protocol settings.
- Fixed rare crashes that could occur when proxy connections were synchronously closed while data was being written.
- Fixed recursive HTTP/3 timer processing that could cause a stack overflow under certain conditions.
  • 👍 11
  • ❤ 5
Post #400 7.07K
DNS Updates

Host rules now support specifying a dedicated DNS server for domain aliases, for example: foo.com = bar.com, server:https://example/dns-query.
  • 👍 17
  • 🤔 6
Post #399 6.44K
iOS TestFlight Updates

New Feature: Terminal
You can now operate Surge directly through the CLI on Surge iOS.
- CLI mode includes a comprehensive set of debugging and diagnostic tools for troubleshooting. For example, the rule explain command can be used to inspect how rules are evaluated and how policy groups make their decisions.
- The new virtual Terminal provides a full interactive experience, including command auto-completion and history. For details on available commands, refer to the Surge Manual or simply run help in the Terminal.

Other reasons why you might want to use Surge from the CLI:
- It’s cool. Maybe even cooler when you’re using it on an iPhone Fold later this year.
- Bringing full CLI capabilities to iOS also lays the groundwork for future AI Agent features on Surge iOS.

New Icons: Arctic & Pulse
- The former Surge Enterprise icon now has a new name: Arctic, and is available for everyone to use.
- Added a new icon: Pulse.
  • ❤ 32
  • 👍 10
  • 🔥 3
  • 🤔 2
Post #398
Channel photo updated
Post #397 5.99K
Prometheus Metrics Endpoint

Surge now provides a Prometheus-compatible metrics endpoint at GET /v1/metrics, making it easy to integrate Surge with Prometheus and Grafana for long-term monitoring and visualization. This is particularly useful for gateway deployments that run continuously.

The endpoint exposes cumulative traffic counters for each network interface and policy (surgeinterface_bytes_total and surge_policy_bytestotal), which can be combined with PromQL functions such as rate() for real-time throughput or increase() for traffic usage over any time window.

It also provides metrics for the Surge engine’s memory footprint (surgememorybytes), in-flight requests, DNS cache size, active unauthorized-access bans, uptime, and build information. The memory metric can be especially useful on iOS for monitoring Network Extension memory usage over time.

The metrics endpoint uses the same authentication mechanism as the rest of the Surge HTTP API. Since Prometheus does not send custom authentication headers by default, the API key can also be supplied through the x-key query parameter:

scrape_configs:
- job_name: surge
metrics_path: /v1/metrics
params:
x-key: ["<your-http-api-key>"]
static_configs:
- targets: ["192.168.1.1:6171"]
  • 👍 19
  • ❤ 1
Post #396 5.26K
Group-Level Proxy Chaining

Surge now supports the group-level underlying-proxy parameter, allowing you to configure a proxy chain for an entire policy group in one place. Every member of the group will connect through the specified policy, including members imported via policy-path, include-all-proxies, and include-other-group.

Chained members are represented as derived policies such as Name (via Relay), each with its own independent latency test result. This means automatic policy groups can select the best node based on its actual performance through the complete proxy chain, rather than the performance of the node alone.

The new option is also fully integrated into the policy group editor UI.

Previously, similar behavior could be achieved with external-policy-modifier="underlying-proxy=...", but that approach only applied to members loaded through policy-path. The new group-level parameter works with members from all sources, provides explicit misconfiguration reporting, and is available as a first-class option in the UI. The existing external-policy-modifier syntax remains supported for backward compatibility.

Please refer to the manual for a detailed comparison and configuration examples:
https://manual.nssurge.com/policy-groups/parameters.html
Nssurge Common Group Parameters · GitBook
  • ❤ 5
  • 👍 4
Post #395 4.62K
Protocol Updates

- Added MASQUE proxy support, using HTTP/3 CONNECT for multiplexed TCP tunnels and CONNECT-UDP for UDP datagrams.
- Added UDP relay support to HTTP/2 CONNECT proxies with udp-relay=true.
- Added HTTP/3 transport support to TrustTunnel with h3=true.
  • ❤ 1
Post #394 4.49K
New Surge Beta Feed on X

We’ve launched @SurgeBeta, a new X account for detailed updates on the latest Surge Beta releases. It will stay in sync with our existing Telegram Channel.

Follow @SurgeBeta to keep up with the latest Beta changes and improvements.
  • ❤ 2
Older posts →

About this channel

How can I read @surgetestflightfeed without a Telegram account?
TGViewer shows the public web preview Telegram publishes for Surge TestFlight Feed: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does Surge TestFlight Feed have?
Surge TestFlight Feed (@surgetestflightfeed) has 12.9K subscribers on Telegram, refreshed roughly every 30 minutes.
Does Surge TestFlight Feed know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →